Skip to main content
Vulnerability Database/CVE-2026-100609

CVE-2026-100609: Flowise Authentication Bypass Vulnerability

CVE-2026-100609 is an authentication bypass vulnerability in Flowise that allows authenticated users to access credentials from other workspaces. This post explains its technical details, affected versions, and mitigation steps.

Published:

CVE-2026-100609 Overview

CVE-2026-100609 is an Insecure Direct Object Reference (IDOR) vulnerability in Flowise, affecting the flowise and flowise-components npm packages through version 3.1.4. The application looks up credentials by ID using findOneBy({ id: credentialId }) without filtering on the requesting user's workspace. An authenticated user in one workspace can supply a credential UUID belonging to another workspace. The server then decrypts and uses the victim workspace's OpenAI or ElevenLabs API key on the attacker's behalf. The flaw maps to [CWE-639: Authorization Bypass Through User-Controlled Key]. No patched version was available at the time of publication.

Critical Impact

Authenticated cross-workspace API key abuse enables attackers to consume and effectively exfiltrate third-party AI service credentials belonging to other tenants.

Affected Products

  • Flowise npm package flowise through 3.1.4
  • Flowise npm package flowise-components through 3.1.4
  • Deployments integrating OpenAI Assistants, ElevenLabs text-to-speech, and the export-import feature

Discovery Timeline

  • 2026-09-26 - CVE-2026-100609 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-100609

Vulnerability Analysis

Flowise exposes several API endpoints that resolve credentials by their UUID without validating workspace ownership. Affected code paths include getAllOpenaiAssistants and getSingleOpenaiAssistant reachable through GET /api/v1/openai-assistants and GET /api/v1/openai-assistants/:id. The uploadFilesToAssistant handler at POST /api/v1/openai-assistants-file/upload/ is also affected. The deleteAssistant handler at DELETE /api/v1/assistants/:id becomes exploitable after importing a poisoned assistant row via POST /api/v1/export-import/import. The shared helper used by getVoices at GET /api/v1/text-to-speech/voices carries the same flaw.

Root Cause

The server performs credential lookups with findOneBy({ id: credentialId }) and omits a workspaceId condition. Authorization is implicitly tied to authentication rather than tenancy, so any authenticated user who knows or guesses a credential UUID can reference it. Flowise decrypts the stored secret and uses it in outbound requests to OpenAI or ElevenLabs on the caller's behalf.

Attack Vector

An attacker authenticates to any workspace on a shared Flowise instance. They then issue an API call to one of the affected endpoints, substituting a credentialId belonging to another workspace. Flowise retrieves and decrypts the target credential, invoking the upstream AI provider with the victim's API key. The attacker can enumerate assistants, upload files, trigger text-to-speech calls, or delete imported assistants, all billed and attributed to the victim tenant.

No verified exploitation code is published. See the GitHub Security Advisory GHSA-27w2-26m5-x82c and the VulnCheck Advisory on Flowise for technical details.

Detection Methods for CVE-2026-100609

Indicators of Compromise

  • Requests to /api/v1/openai-assistants, /api/v1/openai-assistants/:id, /api/v1/openai-assistants-file/upload/, /api/v1/assistants/:id, or /api/v1/text-to-speech/voices where the credentialId parameter does not belong to the caller's workspace.
  • Unexpected POST /api/v1/export-import/import activity followed shortly by DELETE /api/v1/assistants/:id calls.
  • Spikes in OpenAI or ElevenLabs API usage, billing anomalies, or rate-limit errors inconsistent with normal workspace workloads.

Detection Strategies

  • Correlate the authenticated user's workspaceId with the workspaceId of the credential record referenced in each request and alert on mismatches.
  • Audit application logs for credential lookups that bypass tenant scoping, especially within handlers that call findOneBy({ id: credentialId }).
  • Baseline per-workspace outbound traffic to api.openai.com and api.elevenlabs.io and alert on deviations.

Monitoring Recommendations

  • Forward Flowise application and reverse-proxy logs to a centralized analytics pipeline for cross-tenant query analysis.
  • Enable upstream provider audit logs (OpenAI usage dashboards, ElevenLabs history) and reconcile them against expected workspace activity.
  • Monitor for export-import operations that introduce assistant rows referencing credential IDs from other workspaces.

How to Mitigate CVE-2026-100609

Immediate Actions Required

  • Restrict Flowise access to trusted users only and disable self-service registration on multi-tenant deployments.
  • Rotate all OpenAI and ElevenLabs API keys stored in Flowise and reduce their scope or spending limits where supported.
  • Disable or gate the export-import endpoint (POST /api/v1/export-import/import) behind administrative review.

Patch Information

No patched version of flowise or flowise-components was available at the time of publication. Track the GitHub Security Advisory GHSA-27w2-26m5-x82c for updates and apply fixed versions once released.

Workarounds

  • Deploy a reverse-proxy or WAF rule that inspects requests to affected endpoints and blocks credentialId values not owned by the authenticated workspace.
  • Segregate tenants by running separate Flowise instances per workspace with isolated credential stores until an upstream fix is published.
  • Revoke unused credentials and prefer short-lived, workspace-scoped API keys with strict upstream quota caps.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.